---
id: CVE-2026-67213
title: >-
  nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet
  and customRandom functions
summary: >-
  nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet
  and customRandom functions. When these functions are configured with a size of
  0, the internal generation loop never satisfies its exit condition and spins
  ind…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-835
vendor: nanoid_project
product: nanoid
affected:
  - 'nanoid >= 3.0.0, < 3.3.17'
  - 'nanoid >= 5.0.0, < 5.1.6'
patched:
  - nanoid 5.1.6
published: '2026-07-29'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:30.340'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-67213'
references:
  - url: >-
      https://github.com/ai/nanoid/commit/cb3626d0f3342fdf179cd425fd9c4fbb92c7d0e7
    label: disclosure@vulncheck.com
  - url: 'https://github.com/ai/nanoid/releases/tag/5.1.6'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/nanoid-before-infinite-loop-via-zero-size-in-customalphabet-and-customrandom
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-07-29T14:41:51.480372Z'
epss: 0.00587
epssPercentile: 0.46376
ingestedAt: '2026-10-08T16:52:14.708Z'
---

## Overview

nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and spins indefinitely, hanging the calling thread. An application that passes an unvalidated, attacker-controlled size of 0 to these functions is exposed to a denial-of-service condition.

## Affected

- `nanoid >= 3.0.0, < 3.3.17`
- `nanoid >= 5.0.0, < 5.1.6`

## Remediation

Upgrade past the affected range:

- `nanoid 5.1.6`
